This works because we've been conditioned to install videochat plugins, no matter the security warnings. Personally I installed a few of these. I remember when running Google Meet without Chrome required some plugin and when Zoom required admin password every now and then to perform an update (even after the Mac vulnerability incident[1]). I hope I'll think twice next time I see a prompt to install a plugin like this…
Phishing scammers impersonate AH employee to drain crypto wallets
31–40 of 40 posts
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#32Title should be "Phishing scammers impersonate Andreessen Horowitz employee to drain crypto wallets"
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#33Re: Phishing scammers impersonate AH employee to drain crypto wallets
#34Why installing an app allows to "drain wallets"? Why does a video chat app, which is installed from untrusted source, have an access to a wallet private key? Why OS allows this?
There is no way to prevent this on the OS level without making an OS as locked down as iOS. Anything less, and the user will find a way to accidentally give admin permissions to random apps. NB: I don't believe that it's the OS's job to protect the user from themselves. Shielding people from consequences of their own actions results in people making worse mistakes later on.
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#35What's scary is if you google Vortax, it comes up like a totally legit videochat app.
My god. Even a marketing article comparing it to Google Meet. https://medium.com/@VorionApp/vortax-vs-google-meet-what-are...
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#36Why installing an app allows to "drain wallets"? Why does a video chat app, which is installed from untrusted source, have an access to a wallet private key? Why OS allows this?
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#37Why installing an app allows to "drain wallets"? Why does a video chat app, which is installed from untrusted source, have an access to a wallet private key? Why OS allows this?
Honestly, trusting the OS to save you is a bad idea. Why people have one omni device that owns their identity and assets and they will install software "someone online" asked them to on it is beyond me. Horrible opsec all around.
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#38Earlier quoted context omitted.
Honestly, trusting the OS to save you is a bad idea. Why people have one omni device that owns their identity and assets and they will install software "someone online" asked them to on it is beyond me. Horrible opsec all around.
It should be safe to install software. Just as opening a page in a browser is safe.
The kind of safety you're talking about is only possible in strictly walled gardens.
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#39Earlier quoted context omitted.
It worked partly because the company website listed the scammer’s Twitter handle as legit
And because OS allows a video chat app to access wallet's private key.
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#40Earlier quoted context omitted.
My god. Even a marketing article comparing it to Google Meet. https://medium.com/@VorionApp/vortax-vs-google-meet-what-are...
Yes, it reads fairly legit too, not LLM copypasta. Wonder if the scammer was literate or they hired an actual copywriter? Probably just reworded a legit writeup of another product, though. But looking for all the "Vortax" bs they put ou there could be a trail to find them.
This raises questions.
What other endeavors, corporations, or practices do we accept as legitimate that are clearly not? FTX is one example that's obvious in retrospect. How about suspect practices that have become legitimized because of the sheer money and power accrued? I'm thinking for example banks that have been caught red-handed doing business with mafias or terrorists but have not been punished. But those are knowns. What are the unknowns?